We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Cybersecurity blog

ISO 27701:2025 — What Actually Changed, and What It Means for Your Certificate

PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

ISO 27701:2025 — What Actually Changed, and What It Means for Your Certificate

A privacy lead at an Indian IT services firm called us in November, fairly pleased with himself. His organisation had held ISO 27701 since 2022, the certificate was on the website, and enterprise questionnaires were going out with it attached. Then a German client's vendor-risk team asked a question he had not planned for: which edition, and what is your transition plan? He had not registered that the standard had been rewritten a month earlier. The certificate was still valid. The answer to the question was not.

ISO/IEC 27701 was republished on 14 October 2025, and it is not a cosmetic refresh. The standard has been rebuilt from an add-on into a management system that stands on its own. If you hold the 2019 certificate, or you were about to start a privacy programme, the shape of the work has changed. This is what changed, what it means in practice, and what you should be doing between now and the deadline.

The headline change: 27701 no longer sits on top of ISO 27001

The 2019 edition was explicitly an extension. You could not certify to it alone — you needed an ISO 27001 ISMS underneath, and 27701 supplemented those clauses with privacy requirements. That single design decision shaped every 27701 project for six years: privacy teams had to wait for, or drag along, an information security certification they may not have needed for its own sake.

The 2025 edition removes that dependency. It is a standalone management system standard, retitled "Information security, cybersecurity and privacy protection — Privacy information management systems — Requirements and guidance", with its own complete set of requirements. You can now certify a Privacy Information Management System (PIMS) without first certifying an ISMS.

Be careful how you read that, though. Standalone does not mean lighter. Because the standard can no longer borrow ISO 27001's controls by reference, it now carries a set of information security controls of its own. You are not escaping security work — you are choosing whether to run it inside a PIMS or alongside an ISMS. For most organisations that already hold ISO 27001, the combined route remains the sensible one, and it is still supported.

The new structure, clause by clause

The 2025 edition adopts the Harmonized Structure — the common skeleton used by ISO 27001:2022, ISO 42001:2023 for AI, ISO 9001 and the rest. If you have implemented any modern ISO management system, Clauses 4 to 10 will feel familiar.

ClauseWhat it coversWhat to watch for
4 — ContextScope, interested parties, PII in scopeNow includes climate-change consideration, per the 2024 amendment applied across ISO management standards
5 — LeadershipPolicy, roles, accountabilityPrivacy accountability must be assigned explicitly, not inherited from the ISMS
6 — PlanningRisk and objectivesThe big one: a privacy risk assessment focused on risk to individuals, distinct from security risk to the organisation
7 — SupportCompetence, awareness, documented informationYour PIMS documentation must be self-contained if you certify standalone
8 — OperationRunning the PIMSOperational privacy processes — DPIAs, rights handling, breach response
9 — Performance evaluationMonitoring, internal audit, management reviewInternal audit programme must cover Annex A controls in their new structure
10 — ImprovementNonconformity, corrective actionStandard HS wording

Clause 6 deserves a pause. In many 2019-era programmes, privacy risk was folded into the information security risk register and scored the same way — likelihood times impact, impact measured in harm to the business. The 2025 edition asks for a privacy risk assessment oriented to risk to the PII principal: the actual person whose data you hold. Those two assessments produce different answers. A dataset that is low-risk to your balance sheet can be high-risk to the individuals in it. If your current register cannot show that distinction, this is your largest gap, and it is a methodology change rather than a documentation change.

Controls moved into Annex A — and there are 78 of them

In 2019 the controls were embedded in the body of the standard, in clauses that supplemented ISO 27001 and ISO 27002. In 2025 they sit where an auditor expects to find them: a structured Annex A, split by the role you play.

Annex A tableApplies toControls
A.1PII controllers — you decide why and how personal data is processed31
A.2PII processors — you process on a controller's instructions18
A.3Information security controls, applicable to both roles29
Total78

Implementation guidance has been separated out into Annex B, so the requirement and the advice on meeting it are no longer interleaved. In practice this makes the Statement of Applicability far cleaner to write and much easier for an auditor to test against.

One honest caveat, because you will see this claimed both ways. Some certification bodies describe the 2025 controls as a restructuring of what already existed rather than a set of genuinely new obligations; others highlight strengthened treatment of areas such as automated decision-making and de-identification. Both readings are defensible, and the difference matters less than it sounds: whichever is true, you still have to re-map every control you claimed in 2019 onto the new Annex A and rebuild your SoA. Do not let a "nothing is really new" summary talk you out of the mapping exercise.

The annexes are where the transition work actually lives

Most of the practical value in the 2025 edition sits behind Annex A, and it is worth knowing what is there before you commission a gap analysis — several of these annexes replace work you would otherwise pay someone to do.

AnnexContentsWhy it matters to you
A78 controls across controller, processor and security tablesThe basis of your new Statement of Applicability
BImplementation guidance, separated from the requirementsRead alongside A when deciding how far to go on each control
CMapping to ISO/IEC 29100 privacy principlesUseful when your policy framework is written around privacy principles
DMapping to the GDPREvidence reuse if you serve EU markets — one control set, two conversations
EMapping to ISO/IEC 27018 and ISO/IEC 29151Relevant if you are a cloud processor already aligned to 27018
FCorrespondence between the 2019 and 2025 editions, both directionsYour transition starting point — do not rebuild the mapping by hand

Annex F is informative rather than normative, so an auditor will not test you against it. That is not a reason to ignore it: Table F.1 maps 2025 controls back to 2019 and Table F.2 maps forward, which between them turn a re-mapping exercise that consumes weeks into one that consumes days.

Dates you actually need in the calendar

DateWhat happens
14 October 2025ISO/IEC 27701:2025 published
31 October 2026Deadline for certification bodies to be accredited to the 2025 edition
31 October 2028End of the transition period — ISO/IEC 27701:2019 certificates cease to be valid

Three years sounds generous. It is the same arithmetic that caught people out on the ISO 27001:2013 to 2022 transition. Your existing certificate stays valid until it expires or the deadline arrives, whichever comes first — so the real constraint is your own certification cycle, not October 2028. If your recertification falls in 2027, that audit is your natural transition point, which means the gap analysis needs to happen in 2026. Working backwards from your next recertification date is the only planning that matters here.

There is also a squeeze worth anticipating. Every 27701-certified organisation in the world is transitioning into the same window, against a finite pool of accredited auditors, and certification bodies themselves only had to be ready by October 2026. Late movers will be competing for audit slots.

If you already hold ISO 27701:2019, here is the work

  • Get your recertification date, and work backwards. That date, not the 2028 deadline, sets your timeline.
  • Run the mapping using Annex F. The standard ships a correspondence table from the 2019 controls to their 2025 equivalents — start there rather than from a blank sheet.
  • Rewrite the Statement of Applicability against the new Annex A structure, split across the controller, processor and security tables. Whether you are a controller, a processor, or both for different processing activities, decide it per activity and document why.
  • Rebuild the privacy risk assessment so risk to individuals is assessed distinctly from risk to the organisation. Expect this to be the longest item.
  • Decide standalone or combined. If you already hold ISO 27001, combined is usually less work and tells a better story to enterprise buyers. If you do not, standalone is now genuinely available and removes a large dependency.
  • Check your PIMS documentation stands on its own if you go standalone — anything that currently cross-references the ISMS needs to be brought inside the PIMS.
  • Re-scope your internal audit programme so the new Annex A structure is covered before the transition audit, not during it.

If you are starting privacy from scratch

Start on the 2025 edition. There is no sensible reason to implement a standard that stops being certifiable in 2028, and no credit for having done so.

For Indian organisations there is a second, more practical reason to move now. The Digital Personal Data Protection Act, 2023 imposes obligations — consent, notice, data-principal rights, breach notification, and heavier duties for Significant Data Fiduciaries — that map closely onto what a PIMS makes you build anyway: knowing what personal data you hold, why, on what lawful basis, for how long, and who it goes to. A PIMS does not make you DPDP-compliant on its own, and anyone who tells you otherwise is selling something. But the two share most of their evidence base, and building them together is materially cheaper than building them twice.

The mistake we expect to see most

Treating this as a documentation exercise. The temptation is to renumber the SoA, refresh the policy pack, and present it at the transition audit. That will survive a light touch and fail a competent one, because the two changes with real teeth — a privacy risk assessment oriented to the individual, and a PIMS that genuinely stands alone — are both changes to how you work, not to what you have written down. The organisations that struggle in 2028 will be the ones that mapped the controls and never revisited the risk methodology.

FAQs

Do we still need ISO 27001 to certify to ISO 27701:2025?

No. The 2025 edition is a standalone management system standard and no longer depends on ISO/IEC 27001 or 27002. Combined certification remains available and is usually the more efficient route if you already hold ISO 27001, because the two systems share governance, internal audit and management review.

When do ISO 27701:2019 certificates expire?

The transition period ends on 31 October 2028. Existing certificates remain valid until they expire or that date arrives, whichever is first. In practice your own recertification cycle will force the decision earlier, so plan from your next recertification date.

How many controls are in ISO 27701:2025?

Annex A contains 78 controls: 31 for PII controllers, 18 for PII processors, and 29 information security controls that apply to both. Implementation guidance sits separately in Annex B.

Is the transition just a paperwork update?

No. Two changes require real work: Clause 6 asks for a privacy risk assessment focused on risk to the individual rather than to the organisation, and a standalone PIMS must be self-contained rather than cross-referencing an ISMS. The control mapping is the easy part.

Does ISO 27701 make us compliant with India's DPDP Act?

No single certification makes you DPDP-compliant. DPDP is law and ISO 27701 is a voluntary management standard. That said, they overlap heavily on data inventory, lawful basis, retention, data-principal rights and breach response, so a well-run PIMS supplies much of the evidence a DPDP programme needs — and demonstrates diligence if you are ever asked to show it.

We are a processor, not a controller. Does much change for us?

Yes. Processor obligations now sit in their own Annex A table (18 controls) rather than being scattered through the 2019 text, which makes your scope clearer both to define and to evidence. Many organisations are a controller for some processing and a processor for others, so decide the role activity by activity and record the reasoning.

Where to start

If you hold the 2019 certificate, the first useful hour is spent on two things: your next recertification date, and an honest look at whether your privacy risk register measures harm to people or harm to the business. Those two answers tell you how much time you have and how much of the work is methodology rather than paperwork. Everything else follows from that.

Naveen Kumar

Naveen Kumar

CyberSigma is a CERT-In empanelled cybersecurity and privacy firm helping organisations with ISO 27701, ISO 27001, SOC 2, PCI DSS and DPDP compliance — delivered by senior auditors.

Free 1-minute check
Free Security Assessment
Get a complimentary, no-obligation assessment from CERT-In empanelled senior auditors.
Try it free →

Leave A Comment

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →